Hi @wbpcode, thanks for the help with the review! The backward-compatibility logic is only needed when old and new versions of Envoy coexist behind the same load balancer, which is mainly the rolling-update use case.
I plan to clean it up with a follow-up PR after the next release, so it won't confuse later contributors.
Originally posted by @zhaohuabing in #42079 (comment)
This is just a reminder for myself to clean up the old oauth2 flow cookies without suffix after the next release.